Vulnerabilities (CVE)

Filtered by vendor Netiq Subscribe
Filtered by product Identity Manager
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-7674 1 Netiq 1 Identity Manager 2019-10-09 5.8 MEDIUM 6.1 MEDIUM
The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection.
CVE-2018-7676 1 Netiq 1 Identity Manager 2019-10-09 4.3 MEDIUM 5.9 MEDIUM
The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information.
CVE-2018-1349 1 Netiq 1 Identity Manager 2019-10-09 5.0 MEDIUM 5.3 MEDIUM
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration.
CVE-2018-1350 1 Netiq 1 Identity Manager 2019-10-09 5.0 MEDIUM 5.3 MEDIUM
The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration.
CVE-2017-7427 1 Netiq 1 Identity Manager 2019-10-09 4.3 MEDIUM 6.1 MEDIUM
Multiple cross site scripting attacks were found in the Identity Manager Plug-in, hosted on iManager 2.7.7.7, before Identity Manager 4.6.1. In certain scenarios it was possible to execute arbitrary JavaScript code in the context of vulnerable application, via user.Context in the Object Selector, via vdtData in the Version discovery and via nextFrame in the Object Inspector and via Host GUID in the System details plugins.
CVE-2016-1592 1 Netiq 1 Identity Manager 2018-09-27 4.3 MEDIUM 6.1 MEDIUM
XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the nrfEntitlementReport.do CGI.
CVE-2015-0787 1 Netiq 1 Identity Manager 2018-09-27 4.3 MEDIUM 6.1 MEDIUM
XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the accessMgrDN value of the forgotUser.do CGI.